Postmarket surveillance for AI/ML-based SaMD is no longer satisfied by periodic manual review. FDA's total product lifecycle framework, Good Machine Learning Practice principles, and Predetermined Change Control Plan guidance collectively expect manufacturers to monitor real-world model performance on an ongoing basis, detect deviation from predefined boundaries, and maintain auditable records connecting model versions to production behavior.
SaMD Postmarket Surveillance: Continuous Monitoring Requirements for Clinical AI
Postmarket surveillance for AI/ML-based SaMD is no longer satisfied by periodic manual review. FDA's total product lifecycle framework, Good Machine Learning Practice principles, and Predetermined Change Control Plan guidance collectively expect manufacturers to monitor real-world model performance on an ongoing basis, detect deviation from predefined boundaries, and maintain auditable records connecting model versions to production behavior.
Regulatory Pillars Shaping Continuous Monitoring
Four overlapping frameworks currently define what FDA expects from postmarket monitoring of AI-enabled devices. None of them prescribe a specific technical implementation, but together they establish that monitoring is a lifecycle obligation, not a one-time filing.
Total Product Lifecycle (TPLC)
FDA's 2021 AI/ML SaMD Action Plan frames postmarket monitoring as continuous, not a one-time filing.
Good Machine Learning Practice
FDA, Health Canada, and MHRA guiding principles include monitoring model performance after deployment.
Predetermined Change Control Plans
Draft PCCP guidance requires manufacturers to pre-specify monitoring methods and performance boundaries.
QMSR Alignment
The finalized Quality Management System Regulation aligns U.S. requirements with ISO 13485:2016 ahead of a 2026 compliance date.
Technical Components Required for Continuous Monitoring
Meeting these expectations in practice depends on a small set of technical building blocks, each mapped to a specific regulatory concern.
- 1
Input/output and confidence capture
Production models must have their inputs, outputs, and confidence scores captured to support downstream drift analysis without introducing unmanaged PHI exposure.
- 2
Statistical drift detection
Comparing input/output distributions over time against a validated baseline is referenced conceptually in GMLP monitoring principles, though FDA does not prescribe a specific method.
- 3
Tamper-evident audit logging
Logs of model version, configuration, and decision outputs must be retrievable to support FDA inspection or internal quality review.
- 4
Version-linked traceability
Monitoring data must be connected to model version control so that any given output can be traced to the model version that produced it.
- 5
Boundary-based policy enforcement
Detecting or blocking outputs outside performance boundaries defined in a PCCP submission aligns monitoring behavior with pre-specified thresholds.
- 6
Routing into existing quality workflows
Detected anomalies should route into existing CAPA and complaint-handling processes rather than operating as a disconnected, standalone alert system.
From Premarket Clearance to Ongoing Lifecycle Oversight
Historically, medical device compliance centered on a single premarket clearance event, followed by adverse event reporting when problems surfaced. FDA's 2021 AI/ML-Based SaMD Action Plan changed this posture for AI-enabled devices by introducing a Total Product Lifecycle approach, which explicitly calls for monitoring real-world AI/ML performance after deployment rather than treating premarket clearance as the end of the compliance obligation. The 2021 Good Machine Learning Practice guiding principles, jointly issued by FDA, Health Canada, and the UK MHRA, reinforce this by including monitoring of deployed model performance among the ten guiding principles for medical device development. The IMDRF SaMD Clinical Evaluation framework similarly treats clinical evaluation as a lifecycle-based process rather than a single premarket event. Together, these frameworks establish that postmarket surveillance for clinical AI is an ongoing operational function, not a document that gets filed once and revisited only during audits.
What Current Guidance Actually Requires
The regulatory obligations that already apply to SaMD remain in force for AI-enabled devices. 21 CFR Part 803 requires manufacturers to report certain adverse events within specified timeframes, and 21 CFR Part 822 authorizes FDA to require postmarket surveillance studies for devices meeting specific risk criteria, though this authority is not universal and depends on device-specific risk determinations. What is new is the layer added by FDA's draft guidance on Predetermined Change Control Plans, issued in April 2023, which asks manufacturers to describe in advance how they will monitor device performance in the field, including methods for detecting performance degradation. A PCCP effectively requires an organization to define acceptable performance boundaries before deployment, which means monitoring infrastructure must be built to detect deviation from those specific boundaries, not generic anomalies.
Manufacturers should also account for the finalized Quality Management System Regulation, which replaces the prior Quality System Regulation and aligns U.S. requirements with ISO 13485:2016 ahead of a 2026 compliance date, since monitoring documentation and recordkeeping practices will need to fit within this updated quality system structure. It is worth noting that no single FDA guidance document currently mandates a specific technical standard for real-time drift detection or audit logging. Expectations are distributed across TPLC, GMLP, and PCCP guidance and remain principle-based rather than prescriptive, which is precisely why many organizations default to periodic manual review instead of continuous technical monitoring.
Operationalizing Monitoring Inside the Quality System
Building the technical capability is only part of the compliance obligation. Monitoring plans should be defined and documented prior to deployment, consistent with FDA's expectation that PCCP-covered changes and their associated monitoring methods be pre-specified rather than developed reactively after a problem occurs. This means engineering, clinical, and regulatory functions need to agree in advance on what counts as a performance boundary, what triggers an alert, and what happens operationally when that alert fires.
Organizations should map existing quality system procedures, including CAPA, complaint handling, and medical device reporting, to automated monitoring outputs so that continuous monitoring augments existing processes instead of creating a parallel, duplicate review track. Data governance controls also need to address patient privacy when production inputs and outputs are retained for drift analysis, since retention sufficient for retrospective performance review can create exposure if not scoped carefully. Cross-functional ownership matters here because postmarket monitoring for clinical AI spans quality, clinical, and technical functions simultaneously, and a monitoring program owned solely by engineering tends to miss the quality system integration that regulators expect to see documented.
Runtime Governance as the Operational Layer
The gap between principle-based FDA expectations and day-to-day operations is where runtime governance becomes relevant. Runtime governance refers to controls that operate on a deployed AI system while it is running in production, rather than controls applied only at design time or during periodic review cycles. In practical terms, this includes runtime monitoring of model behavior, policy enforcement against predefined performance boundaries, and audit logging that records what a model did, under what configuration, and when.
These capabilities map directly to the technical components described above: a PCCP-defined performance boundary is only meaningful if a runtime control can detect when production behavior crosses it, and an audit log is only useful for FDA inspection if it is tamper-evident and tied to a specific model version. Trussed AI provides runtime governance and security for enterprise AI systems, including runtime monitoring, policy enforcement, and audit logging, which are the categories of control referenced throughout this guidance framework. Organizations evaluating how to close their postmarket surveillance gap should treat runtime governance as infrastructure that sits underneath their existing quality system, not as a replacement for it.
Frequently Asked Questions
Does FDA require a specific technical method for drift detection?
No. FDA's Good Machine Learning Practice principles reference monitoring model performance in deployment conceptually, but no current FDA guidance prescribes a specific drift-detection method or monitoring architecture. Expectations are principle-based across TPLC, GMLP, and PCCP guidance.
What is a Predetermined Change Control Plan and how does it relate to monitoring?
A PCCP, addressed in FDA draft guidance issued in April 2023, allows manufacturers to pre-specify planned modifications to an AI-enabled device and the methods they will use to monitor performance and detect degradation, tying monitoring directly to a defined performance boundary.
Does the QMSR transition affect postmarket monitoring documentation?
Yes. The finalized Quality Management System Regulation replaces the prior Quality System Regulation and aligns U.S. requirements with ISO 13485:2016, with a 2026 compliance date. Monitoring documentation and recordkeeping should be structured with this transition in mind.
Close the gap between regulatory expectations and runtime reality
Postmarket surveillance for clinical AI is an ongoing operational obligation. Runtime governance provides the monitoring, policy enforcement, and audit logging layer needed to support it.
Request a Demo